Privacy-Preserving Security Policy Evaluation via Curried Functions

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Cloud-based cyber threat detection systems face challenges in maintaining privacy and scalability due to the need to transmit sensitive data to remote servers for analysis, which can compromise confidentiality and exceed local processing capabilities.

Innovation Solution

A system that employs a cloud analytics server, a trusted data access mediator, and client devices to currying security policy functions, encrypting sensitive parameters, and evaluating privacy-safe curried functions locally, ensuring that sensitive data remains encrypted and processed only on client devices, thus maintaining privacy while allowing for scalable cloud processing.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If all client monitoring data is exported to a remote cloud server for processing, then cloud-based threat analysis capabilities are improved, but data privacy and confidentiality are compromised

Engineering Contradiction:
Improvecloud-based threat analysis capabilityVSAvoiddata privacy and confidentiality
Core Design Contradiction:
ProductivityVSLoss of information

Solution Approach 1:

The patent segments the security policy evaluation process into two distinct parts: (1) currying operations that transform security policies into curried functions, and (2) evaluation operations that execute the curried functions. By separating these operations, the system allows privacy-preserving currying to occur in the cloud while keeping sensitive evaluation data local, thus resolving the contradiction between cloud-based analysis capability and data privacy protection

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces curried functions as an intermediary mechanism between the cloud server and client devices. The currying operation transforms security policies into a form that can be processed in the cloud without exposing sensitive data, while the evaluation operation uses this intermediary form to perform threat analysis. This intermediary approach enables cloud-based processing while maintaining data confidentiality

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If security policy evaluation is performed using multiple parameters in the cloud, then analysis accuracy is improved, but transmission of sensitive data to remote servers increases

Engineering Contradiction:
Improvethreat detection accuracyVSAvoidsensitive data exposure
Core Design Contradiction:
Measurement precisionVSLoss of information

Solution Approach 1:

The patent applies preliminary currying operations to transform security policies into curried functions before they reach the evaluation stage. This preliminary transformation allows the system to prepare the analysis framework in the cloud without transmitting sensitive evaluation parameters, thereby maintaining detection accuracy while preventing data exposure

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent extracts the currying operation from the overall security policy evaluation process and performs it separately in the cloud. This extraction allows sensitive evaluation data to remain on client devices while still enabling accurate threat detection through the pre-processed curried functions, thus resolving the contradiction between analysis accuracy and data transmission

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS11909769B2Technologies for privacy-preserving security policy evaluation
Publication Date: 2024.02.20 MAGENTA SECURITY HOLDINGS LLC
  • US11909769B2 patent drawing
  • US11909769B2 patent drawing
  • US11909769B2 patent drawing

AI summary

Technologies for privacy-safe security policy evaluation are disclosed herein. An example apparatus includes at least one memory, and at least one processor to execute instructions to at least identify one or more non-sensitive parameters of a plurality of policy parameters and one or more sensitive parameters of the plurality of the policy parameters, the plurality of the policy parameters obtained from a computing device in response to a request from a cloud analytics server for the plurality of the policy parameters, encrypt the one or more sensitive parameters to generate encrypted parameter data in response to the identification of the one or more sensitive parameters, and transmit the encrypted parameter data to the cloud analytics server, the cloud analytics server to curry a security policy function based on one or more of the plurality of the policy parameters.